123A9422Q0028 Statement of Work.pdf
PDF 460 KB Posted
- Attached to
- Bio-Plex Systems Maintenance Federal contract opportunity
- Solicitation number
- 123A9422Q0028
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ 123A9422Q0028.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
US Department of Agriculture (USDA)
Statement of Work for
123A9422Q0028
Contents Project General Information
1.0 Scope of Work
2.0 Background
Contractor Requirements
3.0 Technical Requirements / Tasks
4.0 Government Furnished
5.0 Deliverables / Schedule
6.0 Travel
7.0 Contractor’s Key Personnel
8.0 Security Requirements
9.0 Data Rights
10.0 Section 508 – Electronic and Information Technology Standards
Project
Bio-Plex Systems Service Contract
General Information
1.0 Scope of Work
The service contract for the Bio-Plex Systems shall include labor, parts, managing software upgrade, and necessary material to meet manufacturer’s specifications. This equipment is located at the USDA, FSIS, Eastern Laboratory, 950 College Station Road, Athens, GA 30605
2.0 Background
Not applicable
Contractor Requirements
3.0 Technical Requirements / Tasks
The service contract for the Bio-Plex Systems shall include labor, parts, managing software upgrade, and necessary material to meet manufacturer’s specifications. This equipment is located at the USDA, FSIS, Eastern Laboratory, 950 College Station Road, Athens, GA 30605.
The contractor shall cover the following systems effective July 1, 2022 through June 30, 2027:
SERIAL_NO DESCRIPTION
LX10009243401 BioPlex 200 System BP1 LX10006121404 BioPlex 200 System BP2 LXD09147003 Bioplex HTF for BP1 LXSD06129004 BioPlex HTF for BP2 LXY09219101 BioPlex Platform BP1 LXY06131104 BioPlex Platform BP2
Service shall include the following:
1. One preventative maintenance visit scheduled once a year.
2. Re-installation of Bio-Plex Manager proprietary software to maintain proper operation of system to manufacturer’s specifications, if necessary.
3. Upon completion of preventative maintenance, a certification document shall be submitted showing compliance.
4. Unlimited on-site repair visits, including parts, labor and travel expenses.
The contractor will provide documentation to the Contracting Officer's Representative (COR) that all parts and materials used for repairs/maintenance shall meet manufacturer’s specifications. The contractor shall maintain an adequate inventory of spare parts to accommodate the repair of equipment within time limits specified in this SOW. The contractor shall pay charges to ship replacement or repaired equipment to the customer. The contractor shall also pay shipping charges for the return of equipment to the contractor.
The equipment shall be fully operational according to laboratory methodology and serviceable after completion of maintenance and repairs. The COR or designated representative will certify the equipment is performing satisfactorily.
All payments must be billed quarterly in arrears.
4.0 Government Furnished
Hours of Service. Maintenance/repair services shall be provided during normal working hours, 8:00am to 4:00pm EST, Monday through Friday, excluding Federal Holidays (see http://www.opm.gov/Fedhol/ for a listing of the Federal Holidays).
After hours and weekend support shall be provided for a fee.
The Contracting Officer's Representative (COR) will act, on-site, as the technical point of contact for the Government, initiate service calls, and perform acceptance of equipment after maintenance and repairs. The COR’s authority is limited to technical issues and he/she is not authorized to make contractual decisions. The authority to resolve monetary issues and contractual interpretation is the responsibility of the Contracting Officer.
5.0 Deliverables / Schedule
See Section 3.0.
6.0 Travel
See Section 3.0.
7.0 Contractor’s Key Personnel
Not Applicable
8.0 Security Requirements
The contractor shall provide the COR with information on the names of all employees who will require access to the facility to perform work on equipment, including approximate date and time of arrival. This should be provided at least 24 hours in advance of work being performed. All employees provided by contractor must have valid picture identification before being allowed onto the premises.
If the supported item meets the criteria that establish it as an information system, the item must provide for completion of the Assessment and Accreditation (A&A) process in accordance with the USDA Risk Management Framework process Guide to ensure the appropriate security controls and configuration baselines are implemented.
If the supported item meets the criteria that establish it as an information system, the item shall include documentation with information describing the functional properties of the security controls to be employed within the information system, information system components, or information system services in sufficient detail to permit analysis and testing of the controls.
9.0 Data Rights
Not Applicable
10.0 Section 508 – Electronic and Information Technology Standards
(a) This statement of work is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the workforce Investment Act of 1998 (P.L. 105-220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.
(b) The EIT accessibility standards at 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001.
(c) Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194), as specified in http://www.opm.gov/Fedhol/ the contract, as a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:
1. Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or
2. In the case of custom Electronic and Information Technology (EIT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant EIT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.
(d) The contractor must ensure that all EIT products that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.
(e) For every EIT product or service accepted under this contact by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date; whichever shall occur first.
Section 508 Compliance for Communications
The supported item shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this statement of work the statement of work shall take precedence.
Rehabilitation Act, Section 508 Accessibility Standards
1. 29 U.S.C. 794d (Rehabilitation Act as amended)
2. 36 CFR 1194 (508 Standards)
3. www.access-board.gov/sec508/508standards.htm (508 standards)
4. FAR 39.2 (Section 508)
5. USDA Standards, policies and procedures (Section 508)
In addition, all contract deliverables are subject to these 508 standards as applicable.
Regardless of format, all Web content or communications materials produced, including text, audio or video -must conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. All contractors (including subcontractors) or consultants responsible for preparing or posting content must comply with applicable Section 508 accessibility standards, and where applicable, those set forth in the referenced policy or standards documents above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the statement of work, shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the content or communications material identified in this statement of work:
http://www.access-board.gov/sec508/508standards.htm%20(508
36 CFR Part 1194.21 a - l
36 CFR Part 1194.22 a - p
36 CFR Part 1194.31 a - f
36 CFR Part 1194.41 a – c
The contractor shall provide a completed Section 508 Product Assessment Template and the contractor shall state exactly how proposed EIT deliverable(s) meet or does not meet the applicable standards.
The following Section 508 provisions apply for software development material identified in this statement of work:
For software development, software applications, and operating systems the Contractor/Developer/Vendor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.21 (a – l) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For web-based applications (intranet, internet information and applications, 16 rules), the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.22 (a – p) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For Telecommunication products the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources
36 CFR Part 1194.23 (a – k) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For video and multimedia applications (including training), the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.24 (a – e) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For self contained, closed products, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.25 (a – j) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For Desktop and portable computers, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.26(a – d) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508) http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources http://www.access-board.gov/sec508/508standards.htm
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
All Electronic Information Technology that is subject to the 36 CFR 1194 standards will have a Section 508 acceptance test and Section 508 will be validated upon acceptance.
All maintenance for Electronic Information Technology that requires upgrades, modifications, installations and purchases will adhere to the Section 508 Standards and 36 CFR 1194.
SECTION 508 COMPLIANCE ACCESSIBILITY OF ELECTRONIC AND INFORMATION TECHNOLOGY
(MAR 2015)
(a) This SOW/PWS or TO is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the workforce Investment Act of 1998 (P.L. 105-220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Electronic and Information Technology (EIT), the EIT must allow Federal employees and individuals of the public with disabilities comparable access to and use of information and data that is provided to Federal employees and individuals of the public without disabilities.
(b) The EIT accessibility standards at 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board ("Access Board") and apply to contracts and task/delivery orders, awarded under indefinite quantity contracts on or after June 25, 2001.
(c) Each Electronic and Information Technology (EIT) product or service furnished under this contract shall comply with the Electronic and Information Technology Accessibility Standards (36 CFR 1194), as specified in the contract, as a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within the period of time to be specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:
1. Cancellation of the contract, delivery or task order, purchase or line item without termination liabilities; or
2. In the case of custom Electronic and Information Technology (EIT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant EIT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.
(d) The contractor must ensure that all EIT products that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.
(e) For every EIT product or service accepted under this contact by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date; whichever shall occur first.
Section 508 Compliance for Communications
The vendor shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents, the SOW shall take precedence.
Rehabilitation Act, Section 508 Accessibility Standards
1. 29 U.S.C. 794d (Rehabilitation Act as amended)
2. 36 CFR 1194 (508 Standards)
3. www.access-board.gov/sec508/508standards.htm (508 standards)
4. FAR 39.2 (Section 508)
5. USDA Standards, policies and procedures (Section 508) http://www.access-board.gov/sec508/508standards.htm%20(508
In addition, all contract deliverables are subject to these 508 standards as applicable.
Regardless of format, all Web content or communications materials produced, including text, audio or video -must conform to applicable Section 508 standards to allow federal employees and members of the public with disabilities to access information that is comparable to information provided to persons without disabilities. All contractors (including subcontractors) or consultants responsible for preparing or posting content must comply with applicable Section 508 accessibility standards, and where applicable, those set forth in the referenced policy or standards documents above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the content or communications material identified in this SOW:
36 CFR Part 1194.21 a - l 36 CFR Part 1194.22 a - p 36 CFR Part 1194.31 a - f 36 CFR Part 1194.41 a – c
The contractor shall provide a completed Section 508 Product Assessment Template and the contractor shall state exactly how proposed EIT deliverable(s) meet or does not meet the applicable standards.
The following Section 508 provisions apply for software development material identified in this SOW, PWS, or
TO:
For software development, software applications, and operating systems the Contractor/Developer/Vendor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.21 (a – l) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources For web-based applications (intranet, internet information and applications, 16 rules), the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.22 (a – p) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For Telecommunication products the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.23 (a – k) http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources
36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For video and multimedia applications (including training), the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.24 (a – e) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources For self-contained, closed products, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.25 (a – j) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For Desktop and portable computers, the Contractor shall comply with the standards, policies, and procedures below:
Rehabilitation Act, Section 508, Accessibility Standards
(1) 29 U.S.C. 794d (Rehabilitation Act as amended)
(2) 36 CFR 1194 (508 Standards) 36 CFR Part 1194.26(a – d) 36 CFR Part 1194.31 (a – f) 36 CFR Part 1194.41 (a – c)
(3) www.access-board.gov/sec508/508standards.htm (508 Standards)
(4) FAR 39.2 (Section 508)
(5) USDA Standards, policies and procedures (Section 508)
a. Information Technology – General Information http://www.ocio.usda.gov/508/index.html#resources
For the purposes of this SOW, the Contractor shall review the complete system for 508 compliance and correct all deficiencies or document exceptions as required by departmental and federal requirements.
All Electronic Information Technology that is subject to the 36 CFR 1194 standards will have a Section 508 acceptance test and Section 508 will be validated upon acceptance.
All maintenance for Electronic Information Technology that requires upgrades, modifications, installations and purchases will adhere to the Section 508 Standards and 36 CFR 1194.
http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/508/index.html#resources
POST-AWARD ADMINISTRATION AND MONITORING OF SECTION 508 COMPLIANCE ACCESSIBILITY
OF ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY (MAY 2015)
The Section 508 Plan/Remediation Plan and any modifications to the Plan must be submitted for approval to the Office of the Chief Information Officer (OCIO) or the Department OCIO when the proposed requirement is for, or includes, the acquisition of EIT products and services that are subject to Section 508 conformance provisions as required by departmental and federal requirements. Any exception must be documented and approved by OCIO.
ADDITIONAL PRIVACY ACT REQUIREMENTS (JAN 2012)
For contracts that are awarded with Federal Acquisition Regulations (FAR) and Agriculture Acquisition Regulations (AGAR) concerning the Privacy Act, Food Safety and Inspection Service (FSIS) requests that contractor employees complete Privacy Act training. Contractor employees may take the course at any place of their choice. An acceptable course is one that covers the basics of the Privacy Act. A certificate that shows completion of training is to be provided to the Contracting Officer’s Representative (COR).
Contractor employees are to complete at least one Privacy Act training course within thirty days after contract award and at least once each year thereafter. USDA offers free Privacy Act training for contractor employees that have a current contract. Contractor employees must be assigned to a current contract that is subject to the Privacy Act to receive the free training. The Contracting Officer (CO) and/or COR can be contacted for further information on procedures for Privacy Act training.
COMPLIANCE WITH INTERNET PROTOCOL VERSION (IPv6) (JULY 2010) This contract involves the acquisition of Information Technology (IT) that uses Internet Protocol (IP) Technology. In order to comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6) issued on August 2, 2005, the contractor agrees that: (1) all deliverables that involve IT that uses IP (products, services, software, etc.) will comply with IPv6 standards set forth in the USGv6 Profile (NIST Special Publication 500-267) and interoperate with both IPv4 and IPv6 systems and products; and (2) it has IPv6 technical support for such deliverables. If the contractor plans to offer a deliverable that involves IT that is not compliant with these requirements, the contractor agrees to obtain the Contracting Officer’s approval before starting work on the deliverable.
COMMONLY ACCEPTED SECURITY CONFIGURATIONS FOR WINDOWS OPERATING SYSTEMS
(MARCH 2015)
By delivering applications under this contract/order, the Contractor certifies that such applications are fully functional and operate correctly as intended on systems using the United States Government Configuration Baseline (USGCB), formerly called Federal Desktop Core Configuration (FDCC) and comply with E-authentication and other federal mandates such as LincPass. This includes Internet Explorer 10, Mozilla FireFox 35.0.1 and higher configured to operate on Windows 7, windows 2008, windows 2012 and higher, as well as Androids and IOS mobile devices.
The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The information technology should also use the Windows Installer Service for installation of the default program files directory and should be able to silently install and uninstall. Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
RULES OF BEHAVIOR FOR PRIVILEGED USERS (FEB 2006)
Food Safety and Inspection Service (FSIS)
Information Technology (IT) Security Rules of Behavior for Privileged Users
Version 1.0 February 10, 2006
Introduction
Purpose The intent of the FSIS Rules of Behavior (ROB) for Privileged Users is to recognize the additional responsibilities associated with special access to, and/or privileges associated with, computer resources within the Department or its offices/bureaus/components. The ROB for Privileged Users are in addition to the file:///C:%5CUsers%5Ccmcchesney%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CINetCache%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CINetCache%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CINetCache%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CINetCache%5CContent.Outlook%5CJT01M52B%5CFNiagro1%5CAppData%5CLocal%5CMicrosoft%5CWindows%5CTemporary%20Internet%20Files%5CContent.Outlook%5CQTTFLLXJ%5CAgency%20Clauses%20and%20Provisions%202014.doc#Security_Configurations_IT
Computer System User IT Security General ROB to which all DOJ users are subject. The identification of these responsibilities originates in OMB A-130 and is included in the FSIS IT Security Standards.
“Privileged User” defined:
A privileged user is someone authorized access to departmental/office/bureau/component computer resources when that access provides the capability to alter the properties, behavior or control of the information system/network. It includes, but is not limited to, any of the following types of access:
a. “Super user,” “root,” or equivalent access, such as access to the control functions of the information system/network, administration of user accounts, etc.
b. Access to change control parameters (e.g., routing tables, path priorities, addresses) of routers, multiplexers, and other key information system/network equipment or software.
c. Ability and authority to control and change program files, and other users’ access to data.
d. Direct access to operating system level functions (also called unmediated access) that would permit system controls to be bypassed or changed.
e. Access and authority for installing, configuring, monitoring or troubleshooting the security monitoring functions of information systems/networks (e.g., network/system analyzers; intrusion detection software; firewalls) or in performance of cyber/network operations.
Who is covered by these rules?
These rules extend to all privileged users (FSIS employees and contractors) who use any computing resources that support the mission and functions of the Food Safety and Inspection Service. All privileged users will review and provide signature or electronic verification to these rules annually, or upon change of assigned responsibilities, whichever occurs first.
What are the penalties for Noncompliance?
Compliance with these rules will be enforced through sanctions commensurate with the level of infraction.
Actions may include a verbal or written warning, removal of system access for a specific period of time, reassignment to other duties, or termination, depending on the severity of the violation. In addition, activities that lead to or cause the disclosure of classified information may result in criminal prosecution under the U.S.
Code, Title 18, Section 798, and other applicable statutes.
Responsibilities Complying Privileged Users will:
1. Understand that it is their responsibility to comply with all security measures necessary to prevent the unauthorized disclosure, modification, or destruction of information; follow appropriate system security policies, guidelines and procedures
2. Agree to the FSIS General Rules of Behavior.
3. Minimize exposure and risk by utilizing a separate account to perform privileged functions from general user functions.
4. Not establish or reset any account utilizing the same password for more than one account, and will not provide the user name and password at the same time through the same medium.
5. Grant read or write authority no higher than is granted to him/her (e.g., a component level user administrator shall not assign department level access to another user administrator).
6. Access application programs only for the purpose of creating or maintaining files.
7. Not make modifications to system configurations that could impact availability or security of the system without the approval of the Change Control Board and/or change management process.
8. Not perform general user activities under the same account (user name and password) due to the security requirement for separation of duties.
9. Protect all passwords from unauthorized disclosure.
10. Not share accounts with another privileged user.
11. Make the system available at any time to the SAISO for inspection and review of audit logs.
12. Grant only read-only access to audit files to the Security Auditor; grant access to general system information only if a need-to-know is established and authorization is received from the ISSO.
13. Make the computer(s) available for periodic reviews of the security configuration by independent testers
14. Make changes to system configuration as directed to meet Vulnerability and Patch Management requirements.
15. Immediately record and report any security incidents to the ISSPM.
I acknowledge and understand the responsibilities associated with my role as a Privileged User, and I will comply with the February 10, 2006, Privileged User Rules of Behavior. The Statement of acknowledgement can be provided via email.
Typed Name
Signature Date
(Requirements from LIMS System Security Plan – per NIST sp 800-53, Revision 4)
1. Contractor shall complete the Assessment and Accreditation process in accordance with the USDA Risk Management Framework Process Guide to ensure the appropriate security controls and configuration baselines are implemented commensurate with the information system's categorization. (SSP Control RA-01)
2. All contractor personnel who will access USDA information or information systems shall sign a nondisclosure agreement. (SSP Control CA-01)
3. Contractor shall comply with the following: (SSP Control SA-04)
a. Security functional requirements.
b. Security strength requirements.
c. Security assurance requirements.
d. Security-related documentation requirements.
e. Requirements for protecting security-related documentation.
f. Description of the information system development environment and environment in which the system is intended to operate.
g. Acceptance criteria.
4. Contractors shall provide information describing the functional properties of the security controls to be employed within the information system, information system components, or information system services in sufficient detail to permit analysis and testing of the controls. (SSP Control SA-04(1))
5. Contractor shall provide design and implementation information for the security controls to be employed that includes: NIST-compliant, security-relevant external system interfaces, high-level design, low-level design, source code, hardware schematics and /or other design/implementation information, as determined by the Information System Security Program Manager (ISSPM), at a level of detail determined by the agency and/or agency policy. (SSP Control SA- 04(2))
6. The developer of the information system, system component, or information system service shall identify early in the system development life cycle, the functions, ports, protocols, and services intended for organizational use. (SSP Control SA-04(9))
7. The contractor shall provide administrator documentation for the information system, system component, or information system service that describes: (SSP Control SA-05)
1. Secure configuration, installation, and operation of the system, component, or service;
2. Effective use and maintenance of security functions/mechanisms; and
3. Known vulnerabilities regarding configuration and use of administrative (i.e., privileged) functions;
7. Administrator documentation shall be provided in hard copy and also made available for placement on a shared network drive that is accessible by the (authorized) user community. (SSP Control SA-05)
8. User documentation shall be provided for the information system, system component, or information system service that describes: (SSP Control SA-05)
1. User-accessible security functions/mechanisms and how to effectively use those security functions/mechanisms;
2. Methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner; and
3. User responsibilities in maintaining the security of the system, component, or service;
9. User guides and SOPs shall be provided in hard copy and are also made available for placement on a shared network drive that is accessible by the (authorized) user community. These user documents shall describe user-accessible security features/functions and how to effectively use those security features/functions; as well as methods for user interaction with the system, which enables individuals to use the system in a more secure manner. User documents shall also describe responsibilities in maintaining the security of the information and the system. (SSP Control SA-05)
10. The contractor shall notify the Government when such documentation is either unavailable or nonexistent and notifies the ISSO/ISSPM in response. (SSP Control SA-05)
11. The developer of the information system, system component, or information system service shall: (SSP Control SA- 11)
a. Create and implement a security assessment plan.
b. Perform unit, integration, system, and/or regression testing/evaluation at agency-approved level of depth and coverage consistent with the USDA Risk Management Framework (RMF).
c. Produce evidence of the execution of the security assessment plan and the results of the security testing/evaluation.
d. Implement a verifiable flaw remediation process.
e. Correct flaws identified during security testing/evaluation.
INFORMATION TECHNOLOGY SYSTEMS SECURITY (SEPT 2013)
The activities covered under by this contract shall require the Contractor’s access to Federal Automated Information System or systems, as well as the implementation of new systems. The Offeror’s proposal must include:
(1) A detailed outline (commensurate with the size and complexity of the Statement of Work) of its present and proposed information technology systems security program. The response must demonstrate that it complies with the security requirements of the SOW, the Federal Information Security Management Act of 2002 (FISMA, Public Law 107-347, 44 U.S.C. 3531-3536); Office of Management and Budget (OMB) Circular A-130, Appendix III “Security of Federal Automated Information Systems” (http://www.whitehouse.gov/omb/circulars_a130_a130appendix_iii) and an acknowledgement of its understanding of the security requirements of the SOW.
(2) A signed copy of the USDA FSIS IT Rules of Behavior shall be included with the Offeror’s proposal.
INFORMATION TECHNOLOGY SYSTEMS SECURITY CONTRACT REQUIREMENTS (JAN 2012)
The contractor shall establish and implement appropriate administrative, technical and physical safeguards to ensure the security and confidentiality of sensitive Government information, data, and/or equipment.
The contractor shall comply with IT systems security and/or privacy specifications set forth in FSIS and USDA directives, policy, and procedures; the Computer Security Act of 1987; Office of Management and Budget (OMB) Circular A-130; and the Federal Information Security Management Act of 2002 (FISMA).
Pursuant to FSIS policy, the contractor shall be responsible for assuring that each contractor employee who requires routine unaccompanied physical access to a Federally-controlled facility and/or unaccompanied access to a Federally-controlled information system, including an FSIS-issued computer, completes Computer Security Awareness training prior to performing any work under this contract.
The contractor is required to maintain a listing of all individuals who have completed Computer Security Awareness training and submit this listing to the COR with a copy to the Contracting Officer within ten (10) calendar days of an individual starting work on this contract.”
ACCESS TO SENSITIVE INFORMATION (FEB 2007)
(a) As used in this clause, “sensitive information” refers to information that a contractor has developed at private expense, or that the Government has generated that qualifies for an exception to the Freedom of Information Act, which is not currently in the public domain, and which may embody trade secrets or commercial or financial information, and which may be sensitive or privileged.
(b) To assist the U. S. Department of Agriculture (USDA), Food Safety and Inspection Service (FSIS) in accomplishing management activities and administrative functions, the Contractor shall provide the services specified elsewhere in this contract.
(c) If performing this contract entails access to sensitive information, as defined above, the Contractor agrees to -
(1) Utilize any sensitive information coming into its possession only for the purposes of performing the services specified in this contract, and not to improve its own competitive position in another procurement action.
(2) Safeguard sensitive information coming into its possession from unauthorized use and disclosure.
(3) Allow access to sensitive information only to those employees that need it to perform services under this contract.
(4) Preclude access and disclosure of sensitive information to persons and entities outside of the Contractor’s organization.
(5) Train employees who may require access to sensitive information about their obligations to utilize it only to perform the services specified in this contract and to safeguard it from unauthorized use and disclosure.
(6) Obtain a written affirmation from each employee that he/she has received and will comply with training on the authorized uses and mandatory protections of sensitive information needed in performing this contract.
(7) Administer a monitoring process to ensure that employees comply with all reasonable security procedures, report any breaches to the Contracting Officer, and implement any necessary corrective actions.
(d) The nature of the work on this contract may subject the Contractor and its employees to a variety of laws and regulations relating to ethics, conflicts of interest, corruption, and other criminal or civil matters relating to the award and administration of government contracts. Recognizing that this contract establishes a high standard of accountability and trust, the Government will carefully review the Contractor’s performance in relation to the mandates and restrictions found in these laws and regulations. Unauthorized uses or disclosures of sensitive information may result in termination of this contract for default, or in debarment of the Contractor for serious misconduct affecting present responsibility as a government contractor.
(e) The Contractor shall include the substance of this clause, including this paragraph (e); suitably modified to reflect the relationship of the parties, in all subcontracts that may involve access to sensitive information.
| Project |
| General Information |
| 1.0 Scope of Work |
| 2.0 Background |
| Contractor Requirements |
| 3.0 Technical Requirements / Tasks |
| 4.0 Government Furnished |
| 5.0 Deliverables / Schedule |
| 6.0 Travel |
| 7.0 Contractor’s Key Personnel |
| 8.0 Security Requirements |
| 9.0 Data Rights |
| 10.0 Section 508 – Electronic and Information Technology Standards |
| Introduction |
| Purpose |
Responsibilities
File details come from the government source that posted it. Updated .